Skip to content

Prepare for release v3.106.0 - #2035

Merged
arielkr256 merged 13 commits into
mainfrom
develop
Apr 21, 2026
Merged

arielkr256 merged 13 commits into
mainfrom
develop

Conversation

@alessandrarizzo

Copy link
Copy Markdown
Contributor

Background

Changes

Testing

dependabot Bot and others added 12 commits April 20, 2026 16:29
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
….0.0 (#2017)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…o 3.4.3 (#2019)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
… 6.1.0 (#2020)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…#2030)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…2009)

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: panther-bot-automation <github-service-account-automation@panther.io>
Co-authored-by: panther-bot-automation <github-service-account-automation@panther.io>
Co-authored-by: panther-bot-automation <github-service-account-automation@panther.io>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: panther-bot-automation <github-service-account-automation@panther.io>
@alessandrarizzo
alessandrarizzo requested a review from a team as a code owner April 21, 2026 14:33
@cursor

cursor Bot commented Apr 21, 2026 •

Copy link
Copy Markdown

PR Summary

Medium Risk
Medium risk because it adds many new security detections and deprecates/removes others, which can change alert volume/coverage and pack composition. Workflow action version bumps may also affect CI behavior.

Overview
Detection content update for v3.106.0. Adds multiple new rule-based detections (and supporting index/coverage entries) for AWS CloudTrail/RDS security signals (e.g., console password spraying, suspicious GetSigninToken, IMDS credential use from public IPs, and several RDS abuse/evasion/destruction events), plus a new aws_rds_context helper to standardize RDS alert context.

Deprecates/disables several older scheduled queries/correlation rules (e.g., S3 security-controls correlation rule, various scheduled query-based sprays/scans, and some Dropbox/GSuite/Kubernetes scheduled rules) and updates packs/indexes accordingly; also replaces Okta AD “pantherflow baseline” lookup tables with new SQL-based lookup table definitions (30/90/180d windows).

CI/automation maintenance: bumps GitHub Action pins (configure-aws-credentials, claude-code-action, github-script, action-create-branch, fork sync action) and makes minor lockfile/metadata housekeeping changes (e.g., Pipfile.lock index fields, deprecated.txt entry/newline).

Reviewed by Cursor Bugbot for commit 7b2f2b0. Bugbot is set up for automated code reviews on this repo. Configure here.

@arielkr256
arielkr256 enabled auto-merge April 21, 2026 14:36
@arielkr256
arielkr256 merged commit c47830f into main Apr 21, 2026
19 checks passed

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 7b2f2b0. Configure here.

Comment thread deprecated.txt
global_filter_snyk
global_filter_tailscale
global_filter_tines
AWS.S3.Disable.Security.Controls

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Deprecated rules missing from deprecated.txt tracking file

Medium Severity

This commit adds AWS.S3.Disable.Security.Controls to deprecated.txt but omits six other rules that also receive Status: Deprecated in the same commit: VPCFlow.Port.Scanning, CloudTrail.Password.Spraying, GSuite.Drive.Many.Documents.Deleted, Kubernetes.SecretEnumeration, Dropbox.Many.Deletes, and Dropbox.Many.Downloads. Notably, GSuite.Drive.Many.Documents.Deleted is the only rule in this batch being changed from Enabled: true to Enabled: false, making its omission from the deprecation tracking particularly impactful.

Additional Locations (2)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 7b2f2b0. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

3 participants